Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
October 07, 2008, 10:25:17 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
198000
Posts
22787
Topics
54749
Members
Latest Member:
bingocn
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Firewall
Feedback/Comments/Announcements/News
Defense+ file integrity detection
« previous
next »
Poll
Question:
EDIT by Mod: Changed Topic title to not be a joke
Members can change their own topic titles themselves editing the subject field of their 1st post.
0 (0%)
Please remember to keep this topic polite and avoid personal attacks.
0 (0%)
Please submit suggestions to
Comodo Firewall Wishlist V6
0 (0%)
Total Voters: 0
Pages:
1
2
3
[
4
]
5
Author
Topic: Defense+ file integrity detection (Read 3153 times)
deleiro
Newbie
Offline
Posts: 14
Re: Defense+ file integrity detection
«
Reply #45 on:
July 14, 2008, 01:08:54 PM »
Quote from: gpnx on July 14, 2008, 12:53:08 PM
Thanks, good sugestion - i guess this works for the installations case (removing the executables). Do i see the executables for which i defined policys in the protected files area?. I still believe thou, that my sugestion (1) is needed. There will be cases when a malware/virus/worm will break in via some system process buffer overrun or w/e and can modify exe's for which i have defined rules w/o notification.
It depends how confident are the devs about D+ capability to protect system and other processes from such threats. It's always good to have second line of defense like hash-check every start of rule enabled exe. But if this will be paid with more clumsy Comdo and burdened system I personally prefer to stay like now.
Just my 1 cent.
Logged
gpnx
Comodo Member
Offline
Posts: 27
Re: Defense+ file integrity detection
«
Reply #46 on:
July 14, 2008, 01:11:10 PM »
egemem:
I just did this test with VirtualPC, comodo 3.0.25.378, winxp:
I have notepad2.exe (copy of notepad.exe) in c:\temp
I run it (notepad2.exe), it ask me for accessing the disk, monitor, kb, etc...i allow all.
I have this breakout2.exe , which i downloaded from matousec.com (spellcheck) and i put it in the same "c:\temp" direcotory..
Now, i rename notepad2.exe to notepad2.exe.bak and i rename breakout2.exe to notepad2.exe (no warnings at any of these steps)
Now i run notepad2.exe (which is the breakout2.exe) and it runs w/o any questions asked and uses the notepad2.exe policy and does it malware job (in this case it changes my desktop).
How to protect agains this , which settings i need to use.
This started all this post about need to check that the executable being run is the original one for which policy is being defined.
Logged
deleiro
Newbie
Offline
Posts: 14
Re: Defense+ file integrity detection
«
Reply #47 on:
July 14, 2008, 01:16:27 PM »
Quote from: gpnx on July 14, 2008, 01:11:10 PM
egemem:
I just did this test with VirtualPC, comodo 3.0.25.378, winxp:
I have notepad2.exe (copy of notepad.exe) in c:\temp
I run it (notepad2.exe), it ask me for accessing the disk, monitor, kb, etc...i allow all.
I have this breakout2.exe , which i downloaded from matousec.com (spellcheck) and i put it in the same "c:\temp" direcotory..
..
As far as I understood you were allowed to rename breakout like notepad because Comodo knows you are human. If malware wants to rename itself like trusted application Comodo will interfere
Logged
gpnx
Comodo Member
Offline
Posts: 27
Re: Defense+ file integrity detection
«
Reply #48 on:
July 14, 2008, 01:24:41 PM »
Quote from: deleiro on July 14, 2008, 01:16:27 PM
As far as I understood you were allowed to rename breakout like notepad because Comodo knows you are human. If malware wants to rename itself like trusted application Comodo will interfere
Well, the renaming happened via explorer.exe..what if its get hacked? Does comodo monitors "rename" action?
What if the executable is residing on removable device (which can be modified outside the current machine that comodo monitors)?
«
Last Edit: July 14, 2008, 01:26:31 PM by gpnx
»
Logged
egemen
Administrator
Comodo's Hero
Offline
Posts: 1734
Re: Defense+ file integrity detection
«
Reply #49 on:
July 14, 2008, 01:26:27 PM »
Quote from: gpnx on July 14, 2008, 01:11:10 PM
egemem:
I just did this test with VirtualPC, comodo 3.0.25.378, winxp:
I have notepad2.exe (copy of notepad.exe) in c:\temp
I run it (notepad2.exe), it ask me for accessing the disk, monitor, kb, etc...i allow all.
I have this breakout2.exe , which i downloaded from matousec.com (spellcheck) and i put it in the same "c:\temp" direcotory..
Now, i rename notepad2.exe to notepad2.exe.bak and i rename breakout2.exe to notepad2.exe (no warnings at any of these steps)
Now i run notepad2.exe (which is the breakout2.exe) and it runs w/o any questions asked and uses the notepad2.exe policy and does it malware job (in this case it changes my desktop).
How to protect agains this , which settings i need to use.
This started all this post about need to check that the executable being run is the original one for which policy is being defined.
It is because you are doing all these manually and CFP is configured to allow these by default. Go to computer security policy and remove the entry for %windir%\explorer.exe to see how CFP would catch a virus (assuming explorer.exe is a virus here). Alsotry to use paranoid mode to see as many popups as you can.
Logged
deleiro
Newbie
Offline
Posts: 14
Re: Defense+ file integrity detection
«
Reply #50 on:
July 14, 2008, 01:28:21 PM »
Quote from: gpnx on July 14, 2008, 01:24:41 PM
Well, the renaming happened via explorer.exe..what if its get hacked? Does comodo monitors "rename" action?
Explorer is also with a rule so it's protected from any tampering with it. Yes I think only "read" is not monitored.
Logged
gpnx
Comodo Member
Offline
Posts: 27
Re: Defense+ file integrity detection
«
Reply #51 on:
July 14, 2008, 01:33:16 PM »
Quote from: egemen on July 14, 2008, 01:26:27 PM
It is because you are doing all these manually and CFP is configured to allow these by default. Go to computer security policy and remove the entry for %windir%\explorer.exe to see how CFP would catch a virus (assuming explorer.exe is a virus here). Alsotry to use paranoid mode to see as many popups as you can.
Well, the renaming happened via explorer.exe..what if its get hacked? Does comodo monitors "rename" action?
What if the executable is residing on removable device (which can be modified outside the current machine that comodo monitors).
If i take explorer.exe as you sugested, then i will have too many popups... explorer is part of the system. as many other processes. what if some of them gets hacked? for example, hackers takes over the system via (browers b/o, iis b/o or w/e) and uses explorer to modify system files... all the policy will still work with these modified files.
Also, i thought putting a file in "my protected files" won't allow even trusted/save apps to modify them.
Logged
gpnx
Comodo Member
Offline
Posts: 27
Re: Defense+ file integrity detection
«
Reply #52 on:
July 14, 2008, 01:40:05 PM »
Defend+ in paranoid mode.
i copyied explorer.exe to c:\temp and ran it. couple of popus, which i alloweed. then i used it to rename some exe's. No popups asking for permission. I checked the network policies and i see an entry for the "c:\temp\explorer.exe" , but everything is on "ask" (default?). why no popups when renaming an .exe file ( protected by default).
Logged
psych1610
Global Moderator
Comodo's Hero
Offline
Posts: 841
Re: Defense+ file integrity detection
«
Reply #53 on:
July 14, 2008, 02:07:41 PM »
Again. It seems to me you're doing it. Did you remove %windir%explorer.exe as suggested?
Logged
Please read the Forum Policy below before posting:
http://forums.comodo.com/new_member_information/forum_policy-t1516.0.html
If you can't abide by those guidelines, please don't post.
Vettetech
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 4631
Re: Defense+ file integrity detection
«
Reply #54 on:
July 14, 2008, 02:20:22 PM »
From my knowledge there is no way malware could do what your doing. In order for malware to run you would have had to let it run by allowing it via a D+ alert.
Logged
gpnx
Comodo Member
Offline
Posts: 27
Re: Defense+ file integrity detection
«
Reply #55 on:
July 14, 2008, 02:22:30 PM »
The problem is why when i ran that copy of the explorer.exe it was alloweed to rename existing exe's w/o questions.
Also, again, when a file is in my protected files group, can truested/system apps modify it w/o notification?
Logged
ailef
Computer Security Testing Group
Comodo's Hero
Online
Posts: 471
Re: Defense+ file integrity detection
«
Reply #56 on:
July 14, 2008, 05:07:48 PM »
even if there's no crc file check to see if your exe is the same as usual,
some activity needs to run to change your exe file so D+ will alert u about this.
so to check integrity file can be added but as D+ will alert you if something want to change your exe, anyway u're protected but more protection is always better.
we never know what will happen and if something will not be able to bypass D+ to modify some exe without any alert. but the integrity check will tell that the file is not the same as it was last u used it.
don't know what think comodo coders about including integrity check but D+ is able to block a malware that wants to modify a file so u're protected.
now maybe some exploit is able to break into D+ to modify a file u allowed in rules...
anyway D+ is the best security tool i know and for the moment it's not possible to load something into memory that will change a file without a D+ alert.
there's no popup when u rename the file but when u launch it what's happening?
doesn't D+ alert u about this renamed file when it tries to start?
i tried to rename iexplore.exe in vista but i got a message that i need permission to do that and i can't rename it.
it's a vista protection. I tried to rename another prog into xp pro sp3 that is allowed in D+, when i start the renamed i got a D+ alert as it's exactly the same file except the name.
ezcddax.exe starts but ezcddax2.exe popup a D+ alert.
so even if u can rename a file as the new name is not in D+, u can't launch it without allowing it into D+.
the only possibility is some code able to bypass D+ to inject code into a file allowed and keep the same name.
in this case the modified file will start without any alert.
about monitoring rename file, u'll have to allow the code that will rename a file into D+ or maybe there's some exploit able to rename a file without a D+ alert but with a maybe u do nothing.
Logged
xp pro sp3 & vista ultimate sp1 (both 32bits) - comodo 3.0.25.378 - kav 8.0.0.357 - superadblocker 4.6.0.1000
Kyle
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 961
Re: Defense+ file integrity detection
«
Reply #57 on:
July 14, 2008, 11:03:40 PM »
Gpnx! Please read what the other members are saying! It's not going to get much more clearer than that, whats happening is
YOU
are modifying a program\file using windows explorer, for a
malware
to modify a program file it would have to get access to modify.
Logged
Current Goals;
* Run 10kms without taking a break, 7kms so far.
* 100 push ups, 50 so far.
* Do my bit for the world by joining the army.
* Learn C++ as a long term goal, Currently learning.
Vettetech
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 4631
Re: Defense+ file integrity detection
«
Reply #58 on:
July 14, 2008, 11:12:36 PM »
I have never been hacked ever. Nor have have ever known anyone to get hacked.
Logged
panic
Global Moderator
Comodo's Hero
Offline
Posts: 5461
... and I say to myself, "What a wonderful world"
Re: Defense+ file integrity detection
«
Reply #59 on:
July 14, 2008, 11:50:13 PM »
Quote from: gpnx on July 14, 2008, 02:22:30 PM
Also, again, when a file is in my protected files group, can truested/system apps modify it w/o notification?
Yes, but why would they?
Ask yourself this, under what circumstances would a legitimate
safe trusted
application rename another
safe trusted
application? Other than by deliberate, conscious user intervention, I can't think of one (doesn't mean it doesn't occur, just that I can't think of why it would).
If it were malware attempting to use a trusted application (like explorer.exe) to rename a known trusted application, before explorer.exe could do that, you would have received an alert saying "XYZ.EXE is attempting to access explorer.exe in memory".
THIS
is your clue that somethings not right.
THIS
is where you can prevent the trusted application getting renamed by explorer.exe.
If, on the other hand, the malware attempted to directly manipulate the trusted application, you would have received an alert accordingly.
Hope this helps,
Ewen :-)
«
Last Edit: July 14, 2008, 11:55:13 PM by panic
»
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
Tags:
Pages:
1
2
3
[
4
]
5
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.195 seconds with 21 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com